Impact
A race condition caused by concurrent access to a shared resource in the Windows DNS Server allows an attacker to inject malicious code over the network. The flaw involves improper synchronization and leads to unauthorized code execution, granting the attacker system level privileges on the DNS host.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, and Windows Server 2012 through 2025 including Server Core installations are affected.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity; an attacker can exploit it via the network by sending malicious DNS queries to the server, potentially gaining full control of the machine. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the high severity and network‑based nature suggest a significant risk to organizations running the DNS service.
OpenCVE Enrichment